A US biotech that thinks about European health data at all tends to think about it the way it thinks about US health data: as something locked behind consent forms and business-associate agreements, obtainable through a negotiated arrangement with the institution that holds it, and protected once de-identified. That mental model is built from HIPAA, the Common Rule, and the contractual scaffolding US life sciences erects around every data transfer. The European Health Data Space inverts almost every assumption in it. It does not ask a holder of health data to agree to share; it obliges the holder to make the data available. It does not run on consent; it runs on a public-law permit issued by a state body. And it treats the proprietary character of a dataset not as a shield but as a factor to be weighed, and sometimes overridden, by a regulator the company has never dealt with.1Regulation (EU) 2025/327 of 11 February 2025 on the European Health Data Space (EHDS) [2025] OJ L 2025/327; Art. 1 (subject matter, incl. rules for secondary use of electronic health data).
1. A Data Law That Is Not a Consent Law
The EHDS entered into force on 25 March 2025, but its operative provisions arrive on a schedule that is easy to misread as remote. The general date of application is 26 March 2027; the secondary-use machinery in Chapter IV, together with the bulk of the data categories that feed it, applies from 26 March 2029; and a defined set of categories, including human genetic and genomic data and clinical-trial and study data, only becomes available from 26 March 2031. A further date, 26 March 2035, governs when third countries and international organizations may connect to the Union's cross-border secondary-use infrastructure.2EHDS (n 1), Art. 105 (entry into force 25 March 2025; general application 26 March 2027; Chapter IV from 26 March 2029, save that Art. 55(6), Art. 70, Art. 73(5), Art. 75(1) and (12), Art. 77(4) and Art. 78(6) apply from 26 March 2027; Art. 51(1) points (b), (f), (g), (m), (p) from 26 March 2031; Art. 75(5) from 26 March 2035). A US general counsel reading those dates from 2026 sees a horizon comfortably beyond the near-term planning cycle. The difficulty is that the decisions which determine a company's position under the regime are not the 2029 or 2031 obligations themselves; they are structural choices about EU establishment, vendor contracting, and dataset stewardship that have to be made years before the data starts moving, because they cannot be reversed at the deadline.
What the framework actually does is worth stating precisely, because the US analogue does not exist. The EHDS obliges each Member State to designate one or more health data access bodies, which receive applications, weigh them against a closed list of permitted purposes, and issue a data permit authorizing processing of specified electronic health data inside a secure processing environment.3EHDS (n 1), Art. 2(2)(t) (health data holder: an entity in the healthcare or care sectors, or one developing products or services intended for those sectors, manufacturing wellness applications or performing research in relation to them, that as controller has the right or obligation to process personal electronic health data, or can make non-personal electronic health data available through control of a product's technical design); Art. 50 (natural persons and microenterprises exempt unless a Member State extends the obligations); Art. 55(1) (Member States designate the access bodies); Art. 53(1) (closed list of purposes); Art. 73 (secure processing environment); European Commission, Frequently Asked Questions on the European Health Data Space (version 1.1, 26 March 2026), Q 56. Access is not a matter of the applicant persuading the data's custodian; it is a matter of the applicant satisfying a public authority, which then compels the custodian to supply the data. That is the pivot a US reader has to absorb. The party who controls the data in the ordinary sense, the hospital, the registry, the biobank, the trial sponsor's EU subsidiary, is not the gatekeeper. The state body is, and the custodian's role shifts from owner to obligor.
Under the European Health Data Space, the entity that holds a health dataset is not the entity that decides who may use it; the regime converts holders from owners into obligors, and asks a public authority, not a contract, to set the terms.
Consent, the axis on which the US framework turns, is largely displaced. Access rests on a permit issued under the Regulation rather than on individual authorizations, and the natural person's control is expressed instead through a right to opt out of secondary use, reversible and exercisable without reason, which Member States may override only in narrow public-interest cases.4EHDS (n 1), Art. 71 (right of natural persons to opt out at any time and without reason from processing of their personal electronic health data for secondary use; reversible; narrow Member State override for public-interest purposes under Art. 71(4)). The interaction between that opt-out architecture and the consent-and-legal-basis analysis a sponsor already runs under the GDPR and the Swiss DSG for its clinical activity, examined in Insight 03, is one of the places where a US company most readily assumes an equivalence that does not hold.
2. Who Is a Data Holder, and Why a US Sponsor May Already Be One
The threshold question for a US company is not how to obtain European data but whether the Regulation already reaches its own. The answer runs through the definition of a health data holder, which is wider than the label suggests: not only an entity in the healthcare or care sectors, but any natural or legal person developing products or services intended for those sectors, manufacturing wellness applications, or performing research in relation to them, where that person has, as controller, the right or obligation to process personal electronic health data, or can make non-personal electronic health data available through control of a product's technical design. The Regulation lays down no territorial limit of its own, and the Commission has taken the position that the holder obligations do not reach a US-headquartered sponsor without an established presence in the Union, and that where such a presence exists they fall on the EU-based establishment acting as controller or joint controller.3 The relief in that sentence is narrower than it looks. A US biotech running European operations almost never runs them from the United States as a matter of controllership. It runs them through a German or Irish subsidiary, through EU trial sites, through an EU-based real-world-evidence vendor. Each of those may be the EU-established controller the definition captures, and the parent's non-EU status does not travel down to insulate them.
What the holder must then do is supply. On an approved data permit or health data request, a data holder must make the relevant categories of electronic health data available to the access body within a reasonable time and no later than three months, extendable once by a further three months in justified cases.5EHDS (n 1), Art. 60 (duties of health data holders: make Art. 51 data available on a data permit under Art. 68 or a health data request under Art. 69, within a reasonable time and no later than three months, extendable once by three months); Art. 51 (minimum categories, incl. point (a) EHR data, point (f) human genetic, epigenomic and genomic data, point (m) clinical trial and study data). The categories are not abstract. Article 51 lists them, and they include exactly the datasets a biotech regards as commercially central: data from electronic health records, human genetic, epigenomic and genomic data, other molecular data such as proteomic and transcriptomic information, and data from clinical trials and performance studies. The staggering matters here in a way it does not elsewhere. General electronic-health-record data enters the pool from 2029, but the two categories a biotech most jealously guards, human genetic and genomic data and clinical-trial data, are among those that only become available from 2031. The extra two years read as breathing room. They are better read as the interval in which a company either positions its European datasets deliberately or discovers, at the deadline, that positioning was a decision it made by default.
The definitional edge is sharper than the timeline. Because the obligation attaches to the EU-established controller of the data, the question of which entity in a US group's European structure is that controller is not a formality; it determines who carries the supply duty, who must field an access body's request, and whose datasets are in scope. A sponsor that has never mapped controllership across its EU sites, its academic collaborators, and its RWE vendors has not answered the first question the Regulation asks of it, and the answer is not reliably the one the org chart suggests.
3. The Trade-Secret Problem the Access Regime Creates
For a data-generating company, the uncomfortable feature of a compulsory-access regime is that the compulsion runs against its own proprietary material. A US biotech's EU-held datasets, a curated genomic cohort, a real-world-evidence longitudinal file, the structured output of a completed trial, are precisely the assets it treats as trade secrets, and the EHDS renders them accessible to third parties, including competitors, on a permit the company does not control. The Regulation acknowledges the tension and addresses it, but the manner of the address is the problem rather than the solution.
Article 52 requires a data holder to inform the access body of the electronic health data that carry content protected by intellectual property rights, trade secrets, or the regulatory data protection right attaching to a marketing-authorization dossier, to identify which parts of the datasets are concerned, and to justify the need for the specific protection claimed. The access body must then take appropriate and proportionate legal, organizational, and technical measures to preserve that protection, and it may condition access on contractual arrangements between holder and user, for which the Commission is to develop non-binding model terms. Where granting access would entail a serious risk of infringing intellectual property rights, trade secrets, or the regulatory data protection right, and that risk cannot be addressed in a satisfactory manner, the body is obliged to refuse access and to give the applicant a justification; holder and applicant alike may then complain under Article 81.6EHDS (n 1), Art. 52 (IP, trade secrets and the regulatory data protection right: Art. 52(1) requires such data to be made available for secondary use; the holder must flag the protected parts and justify the need for protection (Art. 52(2)); the access body decides which proportionate measures are necessary and may impose contractual terms drawn from non-binding Commission models (Art. 52(3)–(4)); it must refuse access where a serious risk of infringement cannot be addressed satisfactorily (Art. 52(5)); holder and applicant alike may complain under Art. 81). The structure places the initiative, and the burden, on the holder, and it lodges the decisive judgment with the access body. Whether a given dataset presents a serious risk that cannot be adequately addressed is a determination made by the regulator, not the owner, and the standard is deliberately high: the default is disclosure with safeguards, refusal the exception.
That allocation of judgment is where the US instinct misfires. A US company reads a trade-secret carve-out as a category of exclusion, material one designates as confidential and thereby removes from the pool. The EHDS carve-out is not an exclusion but a weighing, and the weight is assigned by an authority applying criteria that, as of publication, the implementing acts and guidance had not fully settled. A holder that flags too little may find protected material supplied; a holder that flags too much invites a proportionality assessment it does not control. Neither the volume nor the manner of the flag is a matter the company resolves on its own, and the model contractual terms that would give the arrangement predictable shape are, by the Regulation's own design, recommendations rather than rules.
The exposure compounds where the dataset is the product. For a company whose valuation rests on a proprietary genomic or real-world-evidence asset, the prospect that a competitor could obtain permitted secondary-use access to a version of that asset held by an EU establishment is not a compliance detail; it is a diligence item, an investment-risk disclosure, and a reason to revisit where the data is held and by which entity. The question of whether the trade-secret protections a US biotech relies on will survive contact with an access body's proportionality analysis is one the company cannot answer from the statutory text, and the answer depends on facts that only the company holds: the composition of the dataset, the strength of the protection claim, and the safeguards available.
4. Access From the Outside and the Third-Country Gate
The mirror image of the exposure is the opportunity, and it is the reason the EHDS is not merely a defensive problem. The same regime that exposes a biotech's EU datasets to third-party access also opens population-scale European health data for research, algorithm development, and regulatory activity. Article 53 sets the permitted purposes, and the research limb is narrower than it first appears: scientific research related to the health or care sectors qualifies only where it contributes to public health or health technology assessments, or ensures high levels of quality and safety of healthcare, of medicinal products or of medical devices, with the aim of benefiting end-users. Development and innovation activities for products or services, and the training, testing, and evaluation of algorithms, including algorithms in medical devices, in vitro diagnostic medical devices, AI systems, and digital health applications, fall inside that gate rather than beside it, and public-health, policymaking, and statistical purposes are reserved to public sector bodies and Union institutions, including where a third party processes on their behalf. Article 54 fences off prohibited uses, decisions detrimental to individuals, insurance, credit, or employment decisions, advertising and marketing, and the development of harmful products, so that the research value is available but the commercial-exploitation uses a US company might assume are not.7EHDS (n 1), Art. 53(1)(e) (scientific research related to the health or care sectors that contributes to public health or health technology assessments, or ensures high levels of quality and safety of healthcare, medicinal products or medical devices, with the aim of benefiting end-users, including development and innovation activities for products or services and the training, testing and evaluation of algorithms, including in medical devices, IVDs, AI systems and digital health applications); Art. 53(2) (points (a), (b) and (c) reserved to public sector bodies and Union institutions, including third parties acting on their behalf); Art. 54 (prohibited uses: detrimental decisions producing legal, social or economic effects; insurance/credit/employment decisions; advertising and marketing; development of harmful products; activities conflicting with national ethical provisions).
The mechanics of getting in are formal. An applicant submits a health data access application; a health data access body issues or refuses a data permit within three months, extendable by three, and a permit may run for up to ten years; fees apply, enforcement powers include exclusion from access for up to five years, and processing occurs inside a secure processing environment under output controls.8EHDS (n 1), Art. 55 (health data access bodies); Art. 67 (health data access application, submittable by any natural or legal person); Art. 68 (data permit issued or refused within three months, extendable by three; permits up to ten years); Art. 62 (fees); Art. 63 (enforcement: permit revocation; periodic penalty payments on a holder; exclusion of a user from access, or of a persistently uncooperative holder from applying, for up to five years); Art. 73 (secure processing environment). Nothing in the application provision requires the applicant to be European. What conditions a non-EU applicant instead is the third-country access gate: an application from a health data applicant established in a third country is eligible only where that country is recognized, through a Commission implementing act, as allowing Union applicants access to health data held there on conditions no more restrictive than the Regulation's own, or where it has joined the Union's cross-border secondary-use infrastructure as a recognized participant, a route whose own provision does not apply until 26 March 2035. As of publication no implementing act of either kind had been adopted for any third country.9EHDS (n 1), Art. 91 (access for applicants established in a third country, conditioned on Commission-recognized reciprocal access on terms not more restrictive than the Regulation's, or a recognized national contact point); Art. 75 and Art. 75(5) (HealthData@EU; third-country and international-organization participation on equivalent-access conditions, deferred by Art. 105 to 26 March 2035).
The consequence is a two-tier reality that a US company has to see clearly. A US biotech with a genuine EU establishment can apply as a Union-established person to a national access body, inside the regime and independent of any reciprocity finding, while a US biotech operating purely from the United States is thrown onto the third-country gate, its access contingent on a recognition of US reciprocity that, as of publication, did not exist and that the company cannot secure on its own. Establishment is therefore not only the axis that determines whether the company is a data holder exposed to supply duties; it is also the axis that determines whether the company is a near-term data user or an applicant waiting on a reciprocity determination outside its control. The same structural choice sits on both sides of the ledger, and it does not resolve the same way for both.
In the period before 2029 the practical work is neither the permit nor the supply duty but the positioning that precedes both. A US sponsor deciding where its European real-world-evidence contracts sit, whether an EU establishment should hold or should avoid holding certain datasets, and how its trade-secret protections are documented is making choices whose consequences land years later, when the categories open and the access body starts issuing permits. The implementing acts and guidance that will define what compliance and protection actually require were, as of publication, still emerging: the TEHDAS2 joint action published operational guidance for access bodies in May 2026, but that guidance is expressly non-binding, and the Commission's implementing acts were not yet adopted.10EHDS (n 1), Art. 70, Art. 73(5) and Art. 75(12) require the key secondary-use implementing acts by 26 March 2027; as of publication these had not been adopted. TEHDAS2 Joint Action, Guideline for health data access bodies on the procedures and formats for data access, D6.3 (27 May 2026), non-binding.
5. Strategic Considerations
The questions that determine a US biotech's position under the EHDS are not answered by the statutory text, and several turn on facts the company holds privately. Whether the Regulation already reaches a US group's own data turns on which entity in its European structure is the EU-established entity the holder obligations attach to: whether a German or Irish subsidiary, an EU trial site, or an EU-based real-world-evidence vendor carries the supply duty, and whether the parent's non-EU status genuinely keeps a given dataset outside the regime or merely relocates the exposure one level down. None of that is resolved by reading the definition; each depends on a controllership map the company may never have drawn.
The trade-secret question is the one most likely to be underestimated because the US instinct misreads the mechanism. Whether a proprietary genomic cohort or a completed-trial dataset held by an EU establishment will survive an access body's proportionality assessment under Article 52 is not a decision the company makes by designating the material confidential; it is a determination a regulator makes against a serious-risk standard, on criteria the implementing acts had not fully settled as of publication. How much to flag, how to substantiate the protection claim, and whether the available safeguards will be treated as adequate are fact-dependent judgments with no reliable answer in advance, and the model contractual terms that might stabilize them are recommendations, not rules.
For a company that wants European data rather than fears its exposure, the strategic fork is establishment itself. Whether to build or use an EU establishment so as to apply as a Union-established data user through a national access body, or to rely on the third-country gate and a reciprocity recognition that, as of publication, did not exist, is a decision that also determines the company's exposure on the holder side, because the same establishment that eases access is the establishment that carries the supply duty. The two considerations pull in opposite directions, and reconciling them is not a matter a template resolves.
Underneath all of it sits the coordination problem the EHDS shares with every EU health-data instrument. The framework overlays the GDPR and the Swiss DSG, the Data Act, the AI Act, and the clinical-trials regime, and a single dataset can attract obligations under several at once, with the opt-out architecture of the EHDS interacting with the legal-basis analysis a sponsor already runs for its European clinical activity, a tension examined in Insight 03. Whether a US biotech's existing European data governance, built for GDPR compliance and negotiated data-sharing, can be extended to a compulsory-access regime it was never designed for, or whether the EHDS is structural enough to require a rebuild, is a question that depends on the specific entity structure, dataset composition, and commercial strategy that determine, in the first place, whether and how the Regulation applies. These are not questions a compliance template answers. They require analysis tied to the facts.